Description
lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4785
https://github.com/lifion/lifion-verify-deps/commit/be1133d5b78e3caa0004fa60207013dca4e1bf38
Related Vulnerabilities
CVE-2022-35915 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts-upgradeable
CVE-2021-32732 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2020-23811 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2023-44487 Vulnerability in maven package org.eclipse.jetty.http2:http2-common
CVE-2020-35200 Vulnerability in maven package org.igniterealtime.openfire.plugins:clientcontrol